Cybersecurity entity

VirusTotal

Company

Every one of those 2 sits in a single category, threat-intel. Of the tracked stories, 1 of 2 also mention Adform, the most common co-covered peer. That works out to roughly 2 stories per week across a 7-day span. Each story carries 2.5 original sources on average, compared with 2.2 for the broader beat in this window.

Last mentioned: Aug 2, 2026

Entity pulse

Recent coverage · VirusTotal

2 stories
7 avg impact
0% positive
100% negative

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

What the coverage shows about VirusTotal

Every one of those 2 sits in a single category, threat-intel. Of the tracked stories, 1 of 2 also mention Adform, the most common co-covered peer. That works out to roughly 2 stories per week across a 7-day span. Each story carries 2.5 original sources on average, compared with 2.2 for the broader beat in this window. Their average consequence score of 7 runs above the beat's 6.5 for that window. VirusTotal appears in 2 tracked Cybersecurity stories published from July 27, 2026 through August 2, 2026.

Stories tracked
2
Per week
2
Sources per story
2.5

Computed from the 2 stories linked to this entity, with beat comparisons drawn from all 63 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.

Coverage cohort

Appears alongside

Other entities that clear the same relevance threshold in stories also covering VirusTotal. Shared-story counts are live from our verified record — not editorial picks.

Timeline

  1. Public disclosure and media coverage

    Kevin Beaumont publicly releases details of the attack; news outlets The Hacker News and unsafe.sh publish reports.

  2. Malicious code injected into Adform's trackpoint-async.js

    Attackers modify the JavaScript file to swap cryptocurrency wallet addresses. The script is served from s2.adform[.]net to customer sites.

  3. Adform detects and removes the malicious code

    Adform identifies the compromise, deletes the poisoned file, and begins notifying affected clients.

  4. Adform issues cache-clearing advisory

    The company warns that the altered file may remain in browser caches and recommends users clear their cache to prevent continued execution.

  5. Public disclosure

    Fox News publishes a detailed report on ClickLock malware based on Group-IB's findings, raising widespread awareness.

  6. First VirusTotal upload

    Malicious script uploaded to VirusTotal; at the time of analysis, zero detection by any security vendor.

  7. Campaign begins

    ClickLock malware campaign starts targeting Mac users globally through fake CAPTCHA pages.

  8. Kevin Beaumont observes ongoing malicious activity

    Beaumont reports seeing the wallet-swapping behavior via Adform over the past week, extending beyond the initial remediation.

Stories mentioning VirusTotal 2

VirusTotal is linked from 2 stories on this site, each scored at or above our 35% relevance threshold — see how these pages are built.

See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.